시가 총액
24시간 볼륨
10071
암호화폐
58.26%
Bitcoin 공유

North Korean Hackers Steal $21M From SBI Crypto, Laundered via Tornado Cash

North Korean Hackers Steal $21M From SBI Crypto, Laundered via Tornado Cash


cryptonews
2025-10-01 18:47:18

Japanese cryptocurrency company SBI Crypto has fallen victim to a $21 million hack that blockchain investigators have traced to suspected North Korean hackers. The incident adds to a growing list of high-profile cyberattacks attributed to North Korea’s state-backed cyber units, which have stolen billions of dollars from the digital asset sector in recent years. The breach was first flagged by blockchain analyst ZachXBT, who identified suspicious outflows from SBI Crypto wallet addresses on September 24, 2025. Source: ZachXBT SBI Crypto Theft Adds to $2.2B Stolen by North Korean Hackers in 2025 According to his analysis, approximately $21 million worth of cryptocurrency, including Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash, was drained from company-linked addresses. The funds were routed through five instant exchanges before being deposited into Tornado Cash, a crypto mixer frequently associated with laundering operations. On-chain records show that the compromised wallets, including addresses beginning with “0x40d7” and “bc1qx0a2k,” were systematically emptied and funneled through laundering channels. Source: ZachXBT ZachXBT noted that the tactics and digital fingerprints used in the SBI Crypto theft closely resemble other intrusions carried out by the Democratic People’s Republic of Korea (DPRK) cyber units, commonly known as the Lazarus Group. SBI Crypto is a mining pool and wholly owned subsidiary of SBI Group, one of Japan’s largest financial services conglomerates. Despite the scale of the theft, SBI has not yet publicly disclosed the incident. The use of Tornado Cash in the laundering process has drawn renewed scrutiny. The mixer was sanctioned by the U.S. Treasury in 2022 due to its role in processing illicit funds, including those linked to North Korea. Earlier this year, however, a U.S. court lifted restrictions on the platform , sparking concerns that state-backed hackers would once again exploit the service to conceal stolen assets. The SBI incident is the latest in a string of North Korea-linked cyberattacks targeting cryptocurrency exchanges, projects, and users. Data compiled by blockchain forensics firms show that North Korean hackers stole over $1.3 billion across 47 incidents in 2024 alone. In the first half of 2025, they stole an estimated $2.2 billion, showing the growing sophistication and frequency of these operations. North Korean Crypto Campaigns Expand From Hacks to Fraudulent Employment Schemes Investigations into DPRK cyber campaigns have revealed that they extend far beyond hacking wallets and exchanges. On August 13, ZachXBT published evidence of a covert North Korean employment scheme involving five operatives who posed as blockchain developers. ZachXBT exposes 5 North Korean workers running 30+ fake identities to target crypto projects as anonymous source compromises DPRK IT worker devices, revealing $680K Favrr exploit. #NorthKorea #Lazarus https://t.co/ZmPCIZmVpW — Cryptonews.com (@cryptonews) August 13, 2025 These operatives allegedly created more than 30 fake identities using government-issued identification, purchased Social Security numbers, and set up accounts on professional networks such as Upwork and LinkedIn. Files obtained included meeting schedules with targeted projects, Google Drive exports, Telegram conversations, and expense spreadsheets listing purchases of VPNs, AI tools, and fake professional accounts. One of the wallets linked to the fake developer ring was tied to the $680,000 exploit of the crypto project Favrr in June 2025, further connecting the group’s activities to financial crimes. The exposure of these tactics has triggered heightened concern in the cryptocurrency sector. In several cases, projects discovered that developers and decision-makers in their teams were, in fact, North Korean operatives using false identities . ZachXBT links North Korean IT workers to over 25 crypto hacks and extortion schemes beyond simple employment fraud. #NorthKorean #Crypto https://t.co/728cysIs5X — Cryptonews.com (@cryptonews) September 25, 2025 While some companies, such as Kraken, have successfully identified and blocked suspected North Korean applicants, others have been less successful, with millions lost to fraudulent employment schemes and phishing attacks disguised as job offers. Beyond employment fraud, North Korea has been linked to highly sophisticated malware campaigns. In June, cybersecurity firm Cisco Talos documented the “PylangGhost” campaign , in which Lazarus Group operatives created fake coding tests and video interview platforms designed to infect blockchain developers’ devices. The malware targeted over 80 browser extensions, including popular crypto wallets like MetaMask and Phantom. U.S. law enforcement has responded with seizures and arrests tied to DPRK-linked operations. In June, authorities confiscated $7.7 million in cryptocurrency allegedly earned through covert North Korean IT worker networks. Earlier, the FBI dismantled fake companies such as Blocknovas LLC in South Carolina and Softglide LLC in New York, which had been set up to create legitimate corporate fronts for infiltration campaigns. Binance founder @cz_binance issued urgent warnings about North Korean hackers infiltrating crypto companies through fake job applications, urging companies to 'screen candidates carefully.' #CZ #NorthKorean #Hackers https://t.co/jMdd2aYDjg — Cryptonews.com (@cryptonews) September 18, 2025 Former Binance CEO Changpeng Zhao also issued a warning in September, stating that North Korean hackers were increasingly infiltrating crypto firms through fake job applications, bribery of contractors, and malware hidden in interview links. As of press time, the stolen funds remain unaccounted for, and SBI Crypto has yet to issue a formal statement addressing the breach. The post North Korean Hackers Steal $21M From SBI Crypto, Laundered via Tornado Cash appeared first on Cryptonews .


면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.